All Apps and Add-ons

Configuring AWS S3 data input with the exact path

denismo
New Member

I configured the AWS S3 input data source in Splunk Cloud. After specifying the bucket, it presented a choice of paths which are only 2 levels down from the root. Our logs are stored in a location which is 3 levels down, and at 2 levels down we have our data files and logs. So specifying the 2 level folder will ingest all our data and logs which is obviously not desirable.

Is there a way to either specify the exact path from which the logs should be read, or making the configuration UI look 3 levels down?

Thanks.

Denis

Tags (1)
0 Karma

_d_
Splunk Employee
Splunk Employee

Denis, there are two ways to work with S3 data "paths" not available in the dropdown for now: use of blacklists/whitelists or your modify the key_name attribute (i.e. "path") in the inputs.conf file. Also, note that S3 is unlike other filesystems where there is no "hierarchy" per se and each "path" is really a key name that identifies a file/object in your bucket.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...